CVE-2025-62179

🟠 Łataj w tym tygodniu

Wstrzyknięcie SQL w WeGIA umożliwia atakującym wykonanie dowolnych poleceń SQL.

CVSS
8.8
EPSS
0.4%
Exploit
poc
Vendor
wegia
Opis źródłowy (NVD)

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php endpoint, specifically in the cpf parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

exploit sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-10-13 22:15:32 UTC
Ostatnia modyfikacja (NVD)2026-10-08 12:10:00 UTC
Referencje